Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.python > #197902 > unrolled thread
| Started by | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| First post | 2026-09-03 16:30 +0930 |
| Last post | 2026-09-08 08:07 +0300 |
| Articles | 20 on this page of 95 — 18 participants |
Back to article view | Back to comp.lang.python
Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-03 16:30 +0930
Re: Apple changed their documentation at my request but it proves they don't care about privacy Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-09-03 08:09 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-04 02:27 +0930
Re: Apple changed their documentation at my request but it proves they don't care about privacy Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-09-03 20:46 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 06:15 +0600
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-05 00:34 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 07:05 +0600
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-05 01:47 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 14:00 -0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-05 17:49 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 16:14 -0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-06 00:06 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-06 13:39 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-06 15:37 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-06 20:23 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 02:16 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 13:42 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 21:06 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 21:28 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 06:38 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2026-09-07 15:28 -0700
Re: Apple changed their documentation at my request but it proves they don't care about privacy "....winston" <winstonmvp@gmail.com> - 2026-09-07 02:01 -0400
Re: Apple changed their documentation at my request but it proves they don't care about privacy Hank Rogers <Hank@nospam.invalid> - 2026-09-07 01:47 -0500
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-07 10:18 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 13:30 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 21:22 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-07 22:28 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 07:22 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-08 10:44 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-08 13:27 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Lane W <cactus_DAC@yahoo.com> - 2026-09-08 09:47 -0600
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 19:51 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jeff Liebermann <jeffl@cruzio.com> - 2026-09-08 10:23 -0700
Re: Apple changed their documentation at my request but it proves they don't care about privacy Frank Slootweg <this@ddress.is.invalid> - 2026-09-08 18:12 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 22:18 +0400
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jeff Liebermann <jeffl@cruzio.com> - 2026-09-09 19:46 -0700
Re: Apple changed their documentation at my request but it proves they don't care about privacy Johann 'Myrkraverk' Oskarsson <johann@myrkraverk.invalid> - 2026-09-25 23:43 +0800
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jeff Liebermann <jeffl@cruzio.com> - 2026-09-25 13:14 -0700
Re: Apple changed their documentation at my request but it proves they don't care about privacy Johann 'Myrkraverk' Oskarsson <johann@myrkraverk.invalid> - 2026-09-26 04:41 +0800
Re: Apple changed their documentation at my request but it proves they don't care about privacy Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-09-25 22:17 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Johann 'Myrkraverk' Oskarsson <johann@myrkraverk.invalid> - 2026-09-26 07:26 +0800
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-08 18:59 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 21:20 +0400
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-08 19:37 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy "R.Wieser" <address@is.invalid> - 2026-09-08 19:26 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Lane W <cactus_DAC@yahoo.com> - 2026-09-08 11:36 -0600
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-08 20:05 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy "R.Wieser" <address@is.invalid> - 2026-09-08 20:35 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-08 19:06 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Nuno Silva <nunojsilva@invalid.invalid> - 2026-09-07 10:47 +0100
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 13:34 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 18:48 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Nuno Silva <nunojsilva@invalid.invalid> - 2026-09-07 18:46 +0100
Re: Apple changed their documentation at my request but it proves they don't care about privacy Frank Slootweg <this@ddress.is.invalid> - 2026-09-07 14:04 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:47 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Nick Charles <none@none.none> - 2026-09-05 01:11 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 07:24 +0600
Re: Apple changed their documentation at my request but it proves they don't care about privacy Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2026-09-04 23:15 -0700
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 14:18 -0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2026-09-05 16:40 -0700
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 02:40 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:09 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:12 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:13 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:14 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:16 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:18 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 04:23 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2026-09-06 19:03 -0700
Re: Apple changed their documentation at my request but it proves they don't care about privacy Frank Slootweg <this@ddress.is.invalid> - 2026-09-06 11:57 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-09-05 06:44 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 14:35 -0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Paul Rubin <no.email@nospam.invalid> - 2026-09-03 15:48 -0700
Re: Apple changed their documentation at my request but it proves they don't care about privacy Anton Shepelev <anton.txt@gmail.moc> - 2026-09-04 02:02 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 07:46 +0600
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-04 10:28 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-04 11:44 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 20:28 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 21:45 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 21:28 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 07:38 +0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-04 22:58 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 07:13 +0600
Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-05 07:57 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 14:48 -0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Lane W <cactus_DAC@yahoo.com> - 2026-09-05 12:13 -0600
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 15:18 -0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Lane W <cactus_DAC@yahoo.com> - 2026-09-05 12:25 -0600
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 16:22 -0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-06 00:11 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Andy Burns <usenet@andyburns.uk> - 2026-09-05 09:17 +0100
Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-05 11:22 +0000
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 15:13 -0300
Re: Apple changed their documentation at my request but it proves they don't care about privacy "R.Wieser" <address@is.invalid> - 2026-09-06 20:39 +0200
Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 08:07 +0300
Page 1 of 5 [1] 2 3 4 5 Next page →
| From | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| Date | 2026-09-03 16:30 +0930 |
| Subject | Apple changed their documentation at my request but it proves they don't care about privacy |
| Message-ID | <117b5u0$1q77$1@nnrp.usenet.blueworldhosting.com> |
This is an update to the WPS scripts that I posted a few months ago.
Those scripts proved I could collect a list of every single access
point in Apple's database, just as researchers Eric Rye and Dave
Levin did, using a simple perl script which proved the results of
their paper, and which went further to prove that my own
hidden-broadcast SSIDs were in that database.
I complained to my next-door neighbor, who is a top-level exec
at Apple Maps, where he (to his credit) pushed this wording
through, but it proves, yet again, beyond any semblance of
doubt, that Apple doesn't care about our privacy.
Even Google doesn't stoop this low.
And that's saying something.
https://support.apple.com/en-ie/102515
"The owner of a Wi-Fi access point can opt it out of Apple's
Location Services by changing the access point's SSID (name)
to end with _nomap.
For example, ´Access_Point¡ would be changed to ´Access_Point_nomap¡.
This prevents devices from sending the access pointÿs location to
Apple to include in Appleÿs crowd-sourced location database.
This opt-out doesnÿt work for hidden networks because they make
their network name only available to known devices, so other
devices can't detect _nomap."
This last sentence is a bold lie, by the way, since they can
certainly detect it, given the field has a null value.
But they lie about that too.
Below is code reproducing my tests... from which the claims are made.
@echo off
setlocal EnableDelayedExpansion
:: C:\app\os\python\apple_bssid_locator\bssid.bat
:: Use: bssid.bat <Enter> (then enter desired BSSID to look up)
:: Sample values:
:: 00:18:f8:c1:4a:65
:: 00:07:89:d7:82:e8
:: 04:09:A5:3B:34:67
::
:: Logs up to 400 BSSID:GPS pairs from Apple's WPS public database
:: Loop until user types q
::
:: Changelog:
:: v1p0 20251205 - Query Apple's highly insecure WPS database
:: v1p1 20251214 - Saves to time-date stamped results.txt log file
:: v1p2 20251215 - Timestamp results.txt so it's not overwritten
:: v1p3 20251219 - Limit the human-readable GPS to 6 decimal places
:: v1p4 20251219 - Show original raw integers + converted decimals
:: v1p5 20251219 - Tried to accomodate Google Maps query to new format
:: v1p6 20251219 - Changed to block-aware parsing with debug output
:: v1p7 20251219 - Enable delayed expansion to fix parsing inside loops
set LOGDIR=%~dp0log
if not exist "%LOGDIR%" mkdir "%LOGDIR%"
:: Create a unique session log (YYYYMMDD_HHMMSS)
for /f %%A in ('wmic os get localdatetime ^| find "."') do set dt0=%%A
set "session_ts=%dt0:~0,8%_%dt0:~8,6%"
set "session_log=%LOGDIR%\session_%session_ts%.log"
echo === New BSSID lookup session started at %date% %time% === >> "%session_log%"
echo.
echo === Nearby Wi-Fi Networks ===
netsh wlan show networks mode=bssid
echo =============================
:loop
echo.
set /p BSSID=Enter the BSSID (or q to quit):
if /I "%BSSID%"=="q" goto end
:: --- Clean up input ---
set "BSSID=%BSSID:"=%"
set "BSSID=%BSSID: =%"
:: --- Make filename-safe version ---
set "safeBSSID=%BSSID::=-%"
:: --- Generate timestamp for THIS lookup ---
for /f %%A in ('wmic os get localdatetime ^| find "."') do set dt=%%A
set "ts=%dt:~0,8%_%dt:~8,6%"
:: --- Timestamped output file ---
set "outfile=%LOGDIR%\bssid_%safeBSSID%_%ts%.txt"
:: --- Clear previous coordinates ---
set "LAT="
set "LON="
echo === Lookup started at %date% %time% === > "%outfile%"
echo BSSID: %BSSID% >> "%outfile%"
echo. >> "%outfile%"
:: --- Run Python lookup ---
python.exe apple_bssid_locator.py %BSSID% --all >> "%outfile%"
:: --- Display results ---
echo -----------------------------------------------
type "%outfile%"
echo -----------------------------------------------
:: --- Block-aware parsing of coordinates (with delayed expansion) ---
set "CAPTURE="
set "LAT="
set "LON="
for /f "usebackq delims=" %%L in ("%outfile%") do (
if /i "%%L"=="BSSID: %BSSID%" (
set "CAPTURE=1"
set "LAT="
set "LON="
echo [DEBUG] Found block start for %BSSID%
) else if defined CAPTURE (
echo [DEBUG] Line in block: %%L
echo %%L | findstr /i /c:"Latitude (degrees):" >nul
if not errorlevel 1 (
for /f "tokens=2 delims=:" %%A in ("%%L") do set "LAT=%%A"
if defined LAT set "LAT=!LAT: =!"
echo [DEBUG] Parsed LAT candidate = "!LAT!"
)
echo %%L | findstr /i /c:"Longitude (degrees):" >nul
if not errorlevel 1 (
for /f "tokens=2 delims=:" %%B in ("%%L") do set "LON=%%B"
if defined LON set "LON=!LON: =!"
echo [DEBUG] Parsed LON candidate = "!LON!"
)
if defined LAT if defined LON (
goto :gotCoords
)
echo %%L | findstr /i /c:"BSSID:" >nul
if not errorlevel 1 (
set "CAPTURE="
)
)
)
:gotCoords
echo [DEBUG] Final LAT = "!LAT!"
echo [DEBUG] Final LON = "!LON!"
:: --- Validate parsed coordinates ---
if not defined LAT echo [DEBUG][ERROR] Latitude not captured. Check Python output format near "BSSID: %BSSID%".
if not defined LON echo [DEBUG][ERROR] Longitude not captured. Check Python output format near "BSSID: %BSSID%".
:: --- Save results ---
echo === Lookup finished at %date% %time% === >> "%outfile%"
echo. >> "%outfile%"
:: --- Append to session log ---
echo [%date% %time%] BSSID: %BSSID% >> "%session_log%"
echo Latitude: !LAT! >> "%session_log%"
echo Longitude: !LON! >> "%session_log%"
echo. >> "%session_log%"
:: --- Append to master log ---
echo [%date% %time%] BSSID: %BSSID% >> "%LOGDIR%\results.log"
echo Latitude: !LAT! >> "%LOGDIR%\results.log"
echo Longitude: !LON! >> "%LOGDIR%\results.log"
echo. >> "%LOGDIR%\results.log"
:: --- Open in Google Maps ---
if defined LAT if defined LON start msedge "https://www.google.com/maps/search/?api=1&query=!LAT!,!LON!"
goto loop
:end
echo Exiting. Goodbye!
endlocal
:: end of C:\app\os\python\apple_bssid_locator\bssid.bat
[toc] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-09-03 08:09 +0000 |
| Message-ID | <117b9uu$3glj7$1@dont-email.me> |
| In reply to | #197902 |
On Thu, 3 Sep 2026 16:30:15 +0930, Maria Sophia wrote: > Those scripts proved I could collect a list of every single access > point in Apple's database, just as researchers Eric Rye and Dave > Levin did, using a simple perl script which proved the results of > their paper, and which went further to prove that my own > hidden-broadcast SSIDs were in that database. I don’t understand what you’re complaining about, exactly. Your wi-fi network broadcasts its existence to all and sundry, and yet you feel upset when somebody collects that information and passes it on. And hiding SSIDs is a complete waste of time, which gains you nothing in security or privacy. Don’t do it.
[toc] | [prev] | [next] | [standalone]
| From | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| Date | 2026-09-04 02:27 +0930 |
| Message-ID | <117c8t3$ifv$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #197903 |
Lawrence D'Oliveiro wrote: >> Those scripts proved I could collect a list of every single access >> point in Apple's database, just as researchers Eric Rye and Dave >> Levin did, using a simple perl script which proved the results of >> their paper, and which went further to prove that my own >> hidden-broadcast SSIDs were in that database. > > I don't understand what you're complaining about, exactly. Your wi-fi > network broadcasts its existence to all and sundry, and yet you feel > upset when somebody collects that information and passes it on. > > And hiding SSIDs is a complete waste of time, which gains you nothing > in security or privacy. Don't do it. Hi Lawrence, I respect you, but I have to teach you so that you learn what you do not know, as you don't even know that you don't know what you said is wrong. Rest assured, I know what I'm talking about. :) I've discussed this issue with Brian Krebs and Daniel Veditz (of the Mozilla Security Team) so it's quite well understood by professionals. The problem is most people who are NOT Wi-Fi pros, are stuck in the stone age when it comes to thinking about what a hidden broadcast actually does. Worse, I've had to have this discussion a billion times because almost nobody else in the world outside of tech people knows anything about it. The facts is you're thinking about security. Not about privacy. They're not even close to the same thing. This is about privacy. Not security. Apple literally manually removed my SSIDs from their database, as a result of my RADAR bug report and Apple literally changed their documentation. <https://support.apple.com/en-ie/102515> That's new. That's solely because of me. As I had reported months ago, Apple at first pulled the stalling legal trick of saying it's "not reproducible" but the person I had submit that RADAR bug report is an executive in the Apple Maps division who happens to be my next-door neighbor, and he knows full well I know my stuff. They eventually told me "don't use a hidden SSID", which is the wrong answer, and they KNOW it's the wrong answer because they literally manually removed my hidden SSID (but only mine!) from their public WPS database. The entire reason for a hidden SSID is privacy. If the SSID is hidden, it tells everyone you want to be private a. Google respects that b. Mozilla respects that c. Everyone respects that d. Except Apple There's a HUGE difference in what happens to privacy between these events: A. You set the SSID to null B. You append _nomap to your SSID -- Of the million things people need to know about privacy, most know 3.
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-09-03 20:46 +0000 |
| Message-ID | <117cmbk$1e7a$3@dont-email.me> |
| In reply to | #197904 |
On Fri, 4 Sep 2026 02:27:07 +0930, Maria Sophia wrote: > Lawrence D'Oliveiro wrote: >> >> On Thu, 3 Sep 2026 16:30:15 +0930, Maria Sophia wrote: >>> >>> Those scripts proved I could collect a list of every single access >>> point in Apple's database, just as researchers Eric Rye and Dave >>> Levin did, using a simple perl script which proved the results of >>> their paper, and which went further to prove that my own >>> hidden-broadcast SSIDs were in that database. >> >> I don't understand what you're complaining about, exactly. Your >> wi-fi network broadcasts its existence to all and sundry, and yet >> you feel upset when somebody collects that information and passes >> it on. >> >> And hiding SSIDs is a complete waste of time, which gains you nothing >> in security or privacy. Don't do it. > > The problem is most people who are NOT Wi-Fi pros, are stuck in the > stone age when it comes to thinking about what a hidden broadcast > actually does. That’s their problem, though. Trying to offer some kind of sop to their ignorance is not actually making them safer. > This is about privacy. > Not security. This is about the *perception* of privacy. Like telling people they don’t have to worry about closing their curtains, they just need to close their eyes -- if they can’t see the people outside looking in, then those looking in can’t see them! > The entire reason for a hidden SSID is privacy. If the SSID is > hidden, it tells everyone you want to be private “Tells everyone” ... privacy is supposed to be something where you don’t “tell everyone”!
[toc] | [prev] | [next] | [standalone]
| From | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| Date | 2026-09-05 06:15 +0600 |
| Message-ID | <117fmvs$27up$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #197905 |
Lawrence D'Oliveiro wrote: >> This is about privacy. >> Not security. > > This is about the *perception* of privacy. Like telling people they > don't have to worry about closing their curtains, they just need to > close their eyes -- if they can┤ see the people outside looking in, > then those looking in can't see them! Hi Lawrence, I say with all respect that your statement is too wrong to accept as is. What you just said, I've heard a thousand times before, from many people. And yet, it's no different than what I've heard by asking the guy next to me at the gas pump since the 1960's why he puts premium in a Honda Civic. For over five decades, people have been parroting what someone told them. None of them actually understand a word that they're obviously parroting. Same here... Again, I respect you for your technical acumen which is greater'n mine. But I can't tell if you know privacy differences between these situations: a. iPhone owner happens to walk by my house b. Android owner happens to walk by my house Do you know the difference in terms of what happens, or not, with respect to my unique AP BSSID & GPS location (both of which are exactly my house)? I do. A. So does Apple. B. So does Mozilla. And Google. Mozilla respects a hidden access point broadcast (i.e., it's set to null). So does Google (surprisingly). i. But not Apple. ii. And yet, Apple loudly & vociferously proclaims to care about privacy. That's the part that is the most hurtful. Apple brazenly lies, with a huge "what me?" seemingly innocent smile. Yet, Apple immediately removed my BSSID/GPS from their WPS database. Because they know what I know about the lack of privacy in that regard. It may well be I'm the only one in the world who is honored so by Apple. But that's not my point as I care about everyone's privacy. Not just mine. Another question for you, Lawrence, again, because I respect your acumen. Do you know the difference between these two situations: a. iPhone owner happens to walk by my house & it uploads my BSSID/GPS? b. Android owner happens to walk by my house & it uploads my BSSID/GPS? What happens then? Do you know? I do. Anyone who can't answer those queries, can't possibly understand the issue. -- Privacy is a million things, of which most people only understand about 3.
[toc] | [prev] | [next] | [standalone]
| From | Jon Ribbens <jon+usenet@unequivocal.eu> |
|---|---|
| Date | 2026-09-05 00:34 +0000 |
| Message-ID | <slrn119mosh.2a0.jon+usenet@raven.unequivocal.eu> |
| In reply to | #197911 |
On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote: > Lawrence D'Oliveiro wrote: >>> This is about privacy. >>> Not security. >> >> This is about the *perception* of privacy. Like telling people they >> don't have to worry about closing their curtains, they just need to >> close their eyes -- if they can¢t see the people outside looking in, >> then those looking in can't see them! > > Hi Lawrence, > > I say with all respect that your statement is too wrong to accept as is. > What you just said, I've heard a thousand times before, from many people. > > And yet, it's no different than what I've heard by asking the guy next to > me at the gas pump since the 1960's why he puts premium in a Honda Civic. > > For over five decades, people have been parroting what someone told them. > None of them actually understand a word that they're obviously parroting. > > Same here... > > Again, I respect you for your technical acumen which is greater'n mine. > But I can't tell if you know privacy differences between these situations: > a. iPhone owner happens to walk by my house > b. Android owner happens to walk by my house > > Do you know the difference in terms of what happens, or not, with respect > to my unique AP BSSID & GPS location (both of which are exactly my house)? > > I do. > A. So does Apple. > B. So does Mozilla. And Google. > > Mozilla respects a hidden access point broadcast (i.e., it's set to null). > So does Google (surprisingly). > i. But not Apple. > ii. And yet, Apple loudly & vociferously proclaims to care about privacy. > > That's the part that is the most hurtful. > Apple brazenly lies, with a huge "what me?" seemingly innocent smile. > > Yet, Apple immediately removed my BSSID/GPS from their WPS database. > Because they know what I know about the lack of privacy in that regard. > > It may well be I'm the only one in the world who is honored so by Apple. > But that's not my point as I care about everyone's privacy. Not just mine. > > Another question for you, Lawrence, again, because I respect your acumen. > > Do you know the difference between these two situations: > a. iPhone owner happens to walk by my house & it uploads my BSSID/GPS? > b. Android owner happens to walk by my house & it uploads my BSSID/GPS? > > What happens then? > Do you know? > > I do. > Anyone who can't answer those queries, can't possibly understand the issue. Do you have any intention of letting anyone else know what the issue is?
[toc] | [prev] | [next] | [standalone]
| From | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| Date | 2026-09-05 07:05 +0600 |
| Message-ID | <117fpti$18lf$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #197912 |
Jon Ribbens wrote: >> Anyone who can't answer those queries, can't possibly understand the issue. > > Do you have any intention of letting anyone else know what the issue is? Hi Jon, Lil' ole' me can easily track a BSSID anywhere in the world, down to a meter or so accuracy, if I want to under the common circumstances which I've outlined in this thread (and in others). I move my router around a lot, and I don't want just anyone being able to track all my movements down to a meter accuracy when I do that. Do you? You were correct in your prior post to Carlos, when you said (verbatim): "I got the impression they were claiming that their SSID was hidden, which makes it irrelevant as to whether it has "_nomap" at the end of it, but that Apple had somehow discovered and logged it nonetheless. It seems highly implausible." But, of course, there's more detail (which I provided in my responses). I explained it in gory detail, and even provided a link to the research. I provided some of the python scripts too (although they're not the point). We've discussed this ad infinitum on the Apple & Android & Windows ngs in the past, although I don't remember how much we brought in Python folks. What's *new* is Apple told me in my email that there was no way to have WPS privacy from Google/Mozilla if I wished to have WPS privacy from Apple. It's a catch-22 situation. Which would you pick? HINT: If we read the research paper, it's a no brainer which one to pick. -- Of the million things to be considered for privacy, most people know 3.
[toc] | [prev] | [next] | [standalone]
| From | Jon Ribbens <jon+usenet@unequivocal.eu> |
|---|---|
| Date | 2026-09-05 01:47 +0000 |
| Message-ID | <slrn119mt6b.2a0.jon+usenet@raven.unequivocal.eu> |
| In reply to | #197913 |
On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote: > Jon Ribbens wrote: >>> Anyone who can't answer those queries, can't possibly understand the >>> issue. >> >> Do you have any intention of letting anyone else know what the issue >> is? > > Hi Jon, > > Lil' ole' me can easily track a BSSID anywhere in the world, down to a > meter or so accuracy, if I want to under the common circumstances which > I've outlined in this thread (and in others). Ok. I think BSSID means "MAC address of the WiFi access point". I don't know what circumstances you can track them, and you don't seem to have said in this thread. > I move my router around a lot, and I don't want just anyone being able > to track all my movements down to a meter accuracy when I do that. Do > you? I suppose if someone had reason to target me specifically, and they had a real-time way of tracking BSSIDs, and for some reason I can't imagine I was taking a WiFi access point with me, I... oh, wait. In that circumstance I would not take a WiFi access point with me, for the same reason I wouldn't have my mobile phone radio enabled, or would not have a mobile phone with me at all, depending on the threat model. > You were correct in your prior post to Carlos, when you said (verbatim): > "I got the impression they were claiming that their SSID was hidden, > which makes it irrelevant as to whether it has "_nomap" at the end > of it, but that Apple had somehow discovered and logged it nonetheless. > It seems highly implausible." > > But, of course, there's more detail (which I provided in my responses). I saw no response from you to that post. But from what you're saying in the post I'm replying to now, I wasn't correct - I now think you're saying that Apple store the BSSIDs of access points of WiFi networks with hidden SSIDs, because they *don't* know the SSID and therefore can't tell if it has "_nomap" appended, and so don't exclude it. I'm not sure what I think about that, and I don't know what any of the other companies that map SSIDs do in the same situation. I'm not sure why Apple would store location data of BSSIDs with no visible SSID - it doesn't seem like it would help the geolocation feature much, since hiding the SSID is pretty rare. > I explained it in gory detail, and even provided a link to the research. > I provided some of the python scripts too (although they're not the point). You haven't done any of that in this thread so far as I can see. > We've discussed this ad infinitum on the Apple & Android & Windows ngs in > the past, although I don't remember how much we brought in Python folks. > > What's *new* is Apple told me in my email that there was no way to > have WPS privacy from Google/Mozilla if I wished to have WPS privacy > from Apple. Sorry, what does WPS have to do with it? And why is it a binary option? A non-hidden SSID with "_nomap" would presumably provide privacy from all those companies? Or do some of them not support that? Or is having a non-hidden SSID not acceptable to you? If so, what are the options for privacy you are referring to? > It's a catch-22 situation. > Which would you pick? I mean I literally do pick a non-hidden SSID without "_nomap" on it, that I've kept constant for decades. I've never even seen a SSID with "_nomap" on it. There is no-one I regard as a threat, let alone someone who would be a threat and who would know my SSID let alone my BSSIDs. > HINT: If we read the research paper, it's a no brainer which one to pick. What research paper?
[toc] | [prev] | [next] | [standalone]
| From | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| Date | 2026-09-05 14:00 -0300 |
| Message-ID | <117hhrg$1jqn$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #197918 |
Jon Ribbens wrote:
>> Lil' ole' me can easily track a BSSID anywhere in the world, down to a
>> meter or so accuracy, if I want to under the common circumstances which
>> I've outlined in this thread (and in others).
>
> Ok. I think BSSID means "MAC address of the WiFi access point".
> I don't know what circumstances you can track them, and you don't
> seem to have said in this thread.
Hi Jon,
Thanks for your questions as it shows you're trying to understand this.
Your questions are all good questions, from someone who is encountering
this issue for the first time in their lives, but let's be clear that an
entire course in networking for privacy is beyond my personal skill sets.
If you don't know what a BSSID is by now then it will take too much work
here to explain it "fully" to you. Suffice to say it's like a vehicle
identification number on a car. It goes everywhere the router goes.
Every access point has a unique BSSID that stays with the router forever.
(Yes, I know in extremely expensive routers, not home routers, that the
BSSID can be changed, and yes, I know, in those extremely rare situations,
the BSSID may actually not be unique, but only one out of a million people
know those facts, so suffice to say for this thread the BSSID is unique).
The Apple trolls absurdly claimed that changing the SSID changes the BSSID,
but the fact remains the BSSID remains the same no matter what the SSID is.
>> I move my router around a lot, and I don't want just anyone being able
>> to track all my movements down to a meter accuracy when I do that. Do
>> you?
>
> I suppose if someone had reason to target me specifically, and they had
> a real-time way of tracking BSSIDs, and for some reason I can't imagine
> I was taking a WiFi access point with me, I... oh, wait. In that
> circumstance I would not take a WiFi access point with me, for the
> same reason I wouldn't have my mobile phone radio enabled, or would not
> have a mobile phone with me at all, depending on the threat model.
Read the paper which we referenced multiple times in this thread so that I
don't have to re-hash over and over again how mass surveillance is possible
with the Apple WPS database design.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
Anyone who can run a python script (which I will provide to them upon
request) can track anyone in the world who moves from one place to another
(and who happens to take their router with them to their new location).
Nobody disputes that fact, which is what the paper itself explained.
I simply reproduced their "billions of BSSID/GPS pairs" with thousands.
It doesn't bother you that I can track the movements of billions of people
if they happen to move from one locale to another using the same router?
You think this tracking isn't happenging asa we speak?
You think Apple is doing something about it?
That's 1/2 the point of this thread.
1. Apple is doing NOTHING about it (as described in the paper)
2. So anyone in the world can track the movements of billions of routers
2. Worse, Apple isn't honoring the established meaning of the hidden
broadcast (which even Google honors, by way of stark contrast).
So much for Apple "cares about your privacy" bullshit, huh?
It's shocking that google cares about privacy more than Apple does.
>> You were correct in your prior post to Carlos, when you said (verbatim):
>> "I got the impression they were claiming that their SSID was hidden,
>> which makes it irrelevant as to whether it has "_nomap" at the end
>> of it, but that Apple had somehow discovered and logged it nonetheless.
>> It seems highly implausible."
>>
>> But, of course, there's more detail (which I provided in my responses).
>
> I saw no response from you to that post. But from what you're saying
> in the post I'm replying to now, I wasn't correct - I now think you're
> saying that Apple store the BSSIDs of access points of WiFi networks
> with hidden SSIDs, because they *don't* know the SSID and therefore
> can't tell if it has "_nomap" appended, and so don't exclude it.
There are two fundamental issues, only one of which is in this paper.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
I've summarized what's in that paper likely a half dozen times in this
thread, and I've added a second issue that is not discussed in that paper.
I've talked that second issue over with security professionals like Brain
Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims.
To summarize complex issues in a few simple sentences, they might be:
1. Apple allows anyone on the world to track the movements of everyone
in the world (if they take their router with them when they move).
2. Apple puts zero controls on that tracking by anyone, of everyone.
3. In addition, Apple does not respect the known meaning of a hidden
broadcast, and worse, Apple *refuses* to honor what even Google does.
4. Anyone can prove these statements are true on a Windows PC running
Python using the scripts I have provided for that express purpose.
> I'm not sure what I think about that, and I don't know what any of the
> other companies that map SSIDs do in the same situation. I'm not sure
> why Apple would store location data of BSSIDs with no visible SSID -
> it doesn't seem like it would help the geolocation feature much, since
> hiding the SSID is pretty rare.
Remember the Apple trolls posted to this thread that changing the SSID
would solve the issue, but the main issue is about the BSSID, not the SSID.
a. The BSSId is unique (see above for rare exceptions).
b. The GPS location is also unique
c. The SSID only plays a role tangentially, and as such is a minor player
Assume, for an analogous purpose that a flock camera allowed anyone in the
world to track everyone in the world, not only by the license plate (which
can be changed) but by the VIN number, which cannot be changed.
Then assume Flock knows this, but refuses to add any security whatsoever.
a. Worse, assume all the other camera outfits DO add security.
b. Not only that, the other camera outfits add lookup protection.
That's a decent analogy of what's going on that is more easily understood.
>
>> I explained it in gory detail, and even provided a link to the research.
>> I provided some of the python scripts too (although they're not the point).
>
> You haven't done any of that in this thread so far as I can see.
Did you read the paper?
What does that paper say?
Do you know what a hidden broadcast SSID is?
What is the purpose of a hidden broadcast in your opinion?
I've explained both perhaps a half dozen times in this thread.
Explaining another half dozen times won't help until you do the above.
It's unfair of you to claim I haven't provided you an entire courese in
basic networking, when you didn't even click on the links we provided.
>> We've discussed this ad infinitum on the Apple & Android & Windows ngs in
>> the past, although I don't remember how much we brought in Python folks.
>>
>> What's *new* is Apple told me in my email that there was no way to
>> have WPS privacy from Google/Mozilla if I wished to have WPS privacy
>> from Apple.
>
> Sorry, what does WPS have to do with it? And why is it a binary option?
> A non-hidden SSID with "_nomap" would presumably provide privacy from
> all those companies? Or do some of them not support that? Or is having
> a non-hidden SSID not acceptable to you? If so, what are the options
> for privacy you are referring to?
Wrong WPS.
Read the paper.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
>> It's a catch-22 situation.
>> Which would you pick?
>
> I mean I literally do pick a non-hidden SSID without "_nomap" on it,
> that I've kept constant for decades. I've never even seen a SSID with
> "_nomap" on it. There is no-one I regard as a threat, let alone someone
> who would be a threat and who would know my SSID let alone my BSSIDs.
What you need to think about is what the paper explains about the SSID.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
Then, you need to consider what happens when that SSID broadcast is hidden.
Only one out of a million people (or so) has thought about those two things
(but it goes further since now you need to consider what Google/Apple do).
Google does one thing (which, surprisingly, is the right thing to do).
Apple does the opposite (and, not surprisingly, refuses to change it).
If you don't follow the trail from your router to some guy in Russia who is
tracking the movements of everyone in the world, you can't understand it.
Read the paper (which explains half the issues brought up here).
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
>> HINT: If we read the research paper, it's a no brainer which one to pick.
>
> What research paper?
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
--
Most people can only parrot what clever marketing told them to believe.
[toc] | [prev] | [next] | [standalone]
| From | Jon Ribbens <jon+usenet@unequivocal.eu> |
|---|---|
| Date | 2026-09-05 17:49 +0000 |
| Message-ID | <slrn119oli2.8k8.jon+usenet@raven.unequivocal.eu> |
| In reply to | #197924 |
On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote: > Jon Ribbens wrote: >>> Lil' ole' me can easily track a BSSID anywhere in the world, down to a >>> meter or so accuracy, if I want to under the common circumstances which >>> I've outlined in this thread (and in others). >> >> Ok. I think BSSID means "MAC address of the WiFi access point". >> I don't know what circumstances you can track them, and you don't >> seem to have said in this thread. > > Hi Jon, > > Thanks for your questions as it shows you're trying to understand this. > > Your questions are all good questions, from someone who is encountering > this issue for the first time in their lives, but let's be clear that an > entire course in networking for privacy is beyond my personal skill sets. > > If you don't know what a BSSID is by now then it will take too much work > here to explain it "fully" to you. Suffice to say it's like a vehicle > identification number on a car. It goes everywhere the router goes. Well, yes, it's the MAC address, like I already said. >> I suppose if someone had reason to target me specifically, and they had >> a real-time way of tracking BSSIDs, and for some reason I can't imagine >> I was taking a WiFi access point with me, I... oh, wait. In that >> circumstance I would not take a WiFi access point with me, for the >> same reason I wouldn't have my mobile phone radio enabled, or would not >> have a mobile phone with me at all, depending on the threat model. > > Read the paper which we referenced multiple times in this thread so that I > don't have to re-hash over and over again how mass surveillance is possible > with the Apple WPS database design. You hadn't referenced it at the time I wrote my post, or at least by the time you wrote the post I was responding to. It mostly seems to be an attack against people who don't realise they are targets, or are not thinking about the implications - c.f. soldiers who upload their daily runs to public web sites thus revealing if/where they are deployed. > *Surveilling the Masses with Wi-Fi-Based Positioning Systems* > <https://arxiv.org/abs/2405.14975> > > Anyone who can run a python script (which I will provide to them upon > request) can track anyone in the world who moves from one place to another > (and who happens to take their router with them to their new location). > > Nobody disputes that fact, which is what the paper itself explained. > I simply reproduced their "billions of BSSID/GPS pairs" with thousands. > > It doesn't bother you that I can track the movements of billions of people > if they happen to move from one locale to another using the same router? As I say that's a pretty unusual thing to do (travelling with a router). Google's API does seem more sensible though (give it MAC addresses, it tells you where you probably are, rather than giving you the recorded individual locations of all those MAC addresses). > You think this tracking isn't happenging asa we speak? > You think Apple is doing something about it? > > That's 1/2 the point of this thread. > 1. Apple is doing NOTHING about it (as described in the paper) Have you, er, read the paper? It says Apple *is* doing things about it (page 14, section 10 paragraph 3). > 2. So anyone in the world can track the movements of billions of routers > 2. Worse, Apple isn't honoring the established meaning of the hidden > broadcast (which even Google honors, by way of stark contrast). This is the bit I keep asking about and you keep not responding. Is your actual/main complaint that Apple is storing BSSIDs that correspond to hidden SSIDs? And you're saying only Apple do this, not Google etc? > So much for Apple "cares about your privacy" bullshit, huh? > It's shocking that google cares about privacy more than Apple does. Apple cares about the privacy of *its customers*. > There are two fundamental issues, only one of which is in this paper. > *Surveilling the Masses with Wi-Fi-Based Positioning Systems* > <https://arxiv.org/abs/2405.14975> > > I've summarized what's in that paper likely a half dozen times in this > thread, and I've added a second issue that is not discussed in that paper. > > I've talked that second issue over with security professionals like Brain > Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims. > > To summarize complex issues in a few simple sentences, they might be: > 1. Apple allows anyone on the world to track the movements of everyone > in the world (if they take their router with them when they move). > 2. Apple puts zero controls on that tracking by anyone, of everyone. I imagine the issue here is that if they change their API then older devices that are no longer receiving updates will stop being able to do wifi-positioning. > 3. In addition, Apple does not respect the known meaning of a hidden > broadcast, and worse, Apple *refuses* to honor what even Google does. > 4. Anyone can prove these statements are true on a Windows PC running > Python using the scripts I have provided for that express purpose. > >> I'm not sure what I think about that, and I don't know what any of the >> other companies that map SSIDs do in the same situation. I'm not sure >> why Apple would store location data of BSSIDs with no visible SSID - >> it doesn't seem like it would help the geolocation feature much, since >> hiding the SSID is pretty rare. > > Remember the Apple trolls posted to this thread that changing the SSID > would solve the issue, but the main issue is about the BSSID, not the SSID. > a. The BSSId is unique (see above for rare exceptions). > b. The GPS location is also unique > c. The SSID only plays a role tangentially, and as such is a minor player The "Apple trolls" are presumably correct inasmuch as if you change the SSID to end in "_nomap" then it solves the issue. >>> I explained it in gory detail, and even provided a link to the research. >>> I provided some of the python scripts too (although they're not the >>> point). >> >> You haven't done any of that in this thread so far as I can see. > > Did you read the paper? > What does that paper say? You hadn't linked the paper at the time I wrote my post. The paper doesn't quite say what you're claiming, I think, although I see your general point (or at least, the paper's authors' general point). > Do you know what a hidden broadcast SSID is? > What is the purpose of a hidden broadcast in your opinion? To waste power in client devices, as far as I can see, since it means they have to be constantly pinging for the network rather than just connecting to it when they see the SSID broadcast. So in some senses it makes the user tracking problem *much worse*, since it means the attacker can hang around public places watching for client devices (which, unlike access points, tend to move around with the user) that are pinging for the attack target's hidden SSID. Hang around a diner near Langley, Virginia, watching for people carrying devices pinging the hidden SSID "CIA UNCLASSIFIED"... > I've explained both perhaps a half dozen times in this thread. > Explaining another half dozen times won't help until you do the above. I'm starting to think that by "this thread" you don't mean "the set of Usenet articles referenced in the References headers" and are including other historic threads... > Google does one thing (which, surprisingly, is the right thing to do). > Apple does the opposite (and, not surprisingly, refuses to change it). I think you are still failing to explain what those two things are, and I'm getting tired of guessing. If you are claiming the paper describes this difference, please say where. If it doesn't, please just say what it is.
[toc] | [prev] | [next] | [standalone]
| From | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| Date | 2026-09-05 16:14 -0300 |
| Message-ID | <117hplp$oha$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #197928 |
Jon Ribbens wrote:
>> If you don't know what a BSSID is by now then it will take too much work
>> here to explain it "fully" to you. Suffice to say it's like a vehicle
>> identification number on a car. It goes everywhere the router goes.
>
> Well, yes, it's the MAC address, like I already said.
Hi Jon,
To your credit, you are the first person who has responded, who has shown
that he actually *read* the paper before trying to respond intelligently.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
That's good.
Nobody else even bothered to click on the link, before responding.
Hence, everyone else simply parroted their stone-age knowledge level.
You, at least, did *read* the paper, which I congratulate you for doing.
But you did not *understand* what the paper said by the BSSID.
See below where you completely whooshed on which BSSID is what matters.
I must be careful here not to fault you like I fault the Apple trolls,
because I think you are sincerely trying to understand the problem set.
So I simply caution you, as I did Lawrence & Andy, all of whom I respect
for acumen, that you have to follow the trail of the *router* AP BSSID.
You can not "randomize the BSSID" of the router AP (except in the most
expensive commercial routers, which are not the topic of this thread).
Think very deeply about that simple fact before responding, as the crux of
the problem is no different than a governmment-issued identification
number.
You can't easily change your unique government-issued ID number just as you
can't easily change the router-issued BSSID of your home router AP.
Think about that the same way the paper presented the mass surveillance.
1. I wrote a Python script that ran on Windows 10 that guessed at a set
of random government-issued identification numbers, e.g., 123.45.6789
2. Within minutes, I had a hit on a random government ID, which came
back with a GPS location and 400 nearby government IDs and locations.
3. Then, I ran another Python script on Windows 10 that extended that,
taking the furthest-away governemtn ID/location pair, and did it again.
4. Within an hour, I had thousands of government IDs and locations.
(the researchers gathered billions, as I recall, but I stopped there.)
Now that I have every government-issued ID and GPS location in the world in
my 2TB database (which we calculated would be the size it would have been),
what is the paper saying about "mass surveillance" possibilities?
HINT: I can track the future location of every one of those billions of
government ID/GPS location pairs, without any restrictions on my scripts!
Want to prove that?
What's your home router BSSID?
I will not only tell you exactly where that router is located (I even wrote
the Python code to give me a dot on an OSM map for your location) but I can
trivially easily forever track that router's location forever, without any
restrictions on my part (which is the point of the paper, after all).
That's what the paper says.
I went further (i.e., to hidden broadcast issues).
But that alone is what the paper says you can do, and I proved it, and I
supplied the python scripts (and will supply them to anyone who asks me).
>>> I suppose if someone had reason to target me specifically, and they had
>>> a real-time way of tracking BSSIDs, and for some reason I can't imagine
>>> I was taking a WiFi access point with me, I... oh, wait. In that
>>> circumstance I would not take a WiFi access point with me, for the
>>> same reason I wouldn't have my mobile phone radio enabled, or would not
>>> have a mobile phone with me at all, depending on the threat model.
>>
>> Read the paper which we referenced multiple times in this thread so that I
>> don't have to re-hash over and over again how mass surveillance is possible
>> with the Apple WPS database design.
>
> You hadn't referenced it at the time I wrote my post, or at least
> by the time you wrote the post I was responding to.
>
> It mostly seems to be an attack against people who don't realise
> they are targets, or are not thinking about the implications - c.f.
> soldiers who upload their daily runs to public web sites thus
> revealing if/where they are deployed.
It's not "an attack" so much as explaining, with examples, of why we should
care that mass surveillance is so easy with the Apple WPS implementation.
The soldier part is just an example.
I have a more potent example.
Give me your MAC address of your home router AP.
Not only can I instantly tell you where that reouter is, but I can tell you
the location and BSSID of the nearest 400 routers to your location.
We proved that in the Python scripts I had provided and had run on WIn10.
Test me.
Give me your BSSID.
Note: I don't expect you to do it, which alone proves the point.
>> *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
>> <https://arxiv.org/abs/2405.14975>
>>
>> Anyone who can run a python script (which I will provide to them upon
>> request) can track anyone in the world who moves from one place to another
>> (and who happens to take their router with them to their new location).
>>
>> Nobody disputes that fact, which is what the paper itself explained.
>> I simply reproduced their "billions of BSSID/GPS pairs" with thousands.
>>
>> It doesn't bother you that I can track the movements of billions of people
>> if they happen to move from one locale to another using the same router?
>
> As I say that's a pretty unusual thing to do (travelling with a router).
> Google's API does seem more sensible though (give it MAC addresses, it
> tells you where you probably are, rather than giving you the recorded
> individual locations of all those MAC addresses).
I think your claim that it's "pretty unusual" for people to take their
router with them when they move from one apartment to another is skewed.
If I ask 100 people who recently moved, do you really think it would be
only 1 or 2 people who took their home router with them when they moved?
>
>> You think this tracking isn't happenging asa we speak?
>> You think Apple is doing something about it?
>>
>> That's 1/2 the point of this thread.
>> 1. Apple is doing NOTHING about it (as described in the paper)
>
> Have you, er, read the paper? It says Apple *is* doing things about it
> (page 14, section 10 paragraph 3).
See my first response to you in this post, where I want to be careful to
not chastise you for misunderstanding what that paragraph actually says.
You can NOT randomize the MAC address of the router AP, Jon.
Sure, for expensive commercial routers, with thousands of access points,
they can randomize their MAC addresses, but it's not on most home routers.
To be clear, it is on some (expensive) home routers.
I am well aware of that.
But we're talking about surveilling the masses, not the people who actually
know how networking works (which nobody on this thread so far has shown).
>> 2. So anyone in the world can track the movements of billions of routers
>> 2. Worse, Apple isn't honoring the established meaning of the hidden
>> broadcast (which even Google honors, by way of stark contrast).
>
> This is the bit I keep asking about and you keep not responding.
> Is your actual/main complaint that Apple is storing BSSIDs that
> correspond to hidden SSIDs? And you're saying only Apple do this,
> not Google etc?
First off, I don't have a complaint. That's absurd. I have facts.
This entire thread is people disputing those facts, without ever even
bothering to read the links which were provided for them to read.
The absurdity of this thread is nobody has read or understood the links
which were provided, and yet, they ask me (repeatedly) to explain them.
Why can nobody understand the point that Eric & Dave made in this paper?
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
Why can nobody understand what's different about what Apple documented?
<https://support.apple.com/en-ie/102515>
Why can nobody undestqand the concept inherent in a hidden-broadcast?
<https://ichnaea.readthedocs.io/en/stable/api/geosubmit2.html>
"The BSSID of the Wifi network.
Hidden Wifi networks must not be collected."
Why is it that I feel it's trivial to understand that 1+1=2 when everyone
else is trying to claim that I need to explain why 1+2=2 when, if they
simply read (and understood) what I've explained, they would understand?
Can *nobody* actually read those references except me, and understand them?
>
>> So much for Apple "cares about your privacy" bullshit, huh?
>> It's shocking that google cares about privacy more than Apple does.
>
> Apple cares about the privacy of *its customers*.
I realize you're trying to understand these concepts so I have to be
careful when I point out that this affects every single person in the world
who owns a router (and company, but let's restrict this to just people).
The issues are exactly the same no matter what company made that router.
>> There are two fundamental issues, only one of which is in this paper.
>> *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
>> <https://arxiv.org/abs/2405.14975>
>>
>> I've summarized what's in that paper likely a half dozen times in this
>> thread, and I've added a second issue that is not discussed in that paper.
>>
>> I've talked that second issue over with security professionals like Brain
>> Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims.
>>
>> To summarize complex issues in a few simple sentences, they might be:
>> 1. Apple allows anyone on the world to track the movements of everyone
>> in the world (if they take their router with them when they move).
>> 2. Apple puts zero controls on that tracking by anyone, of everyone.
>
> I imagine the issue here is that if they change their API then older
> devices that are no longer receiving updates will stop being able to do
> wifi-positioning.
The issue is clearly obvious that the Apple WPS design is flawed.
I have dozens of emails from Apple, all of which show that they *know* that
their design is flawed.
They're simply trying to protect themselves legally with me by having their
emails redirected to their lawyers, who are whom I was responding with.
They *know* what they're doing is wrong.
>> 3. In addition, Apple does not respect the known meaning of a hidden
>> broadcast, and worse, Apple *refuses* to honor what even Google does.
>> 4. Anyone can prove these statements are true on a Windows PC running
>> Python using the scripts I have provided for that express purpose.
>>
>>> I'm not sure what I think about that, and I don't know what any of the
>>> other companies that map SSIDs do in the same situation. I'm not sure
>>> why Apple would store location data of BSSIDs with no visible SSID -
>>> it doesn't seem like it would help the geolocation feature much, since
>>> hiding the SSID is pretty rare.
>>
>> Remember the Apple trolls posted to this thread that changing the SSID
>> would solve the issue, but the main issue is about the BSSID, not the SSID.
>> a. The BSSId is unique (see above for rare exceptions).
>> b. The GPS location is also unique
>> c. The SSID only plays a role tangentially, and as such is a minor player
>
> The "Apple trolls" are presumably correct inasmuch as if you change the
> SSID to end in "_nomap" then it solves the issue.
No it does not. Did you read any of the Mozilla references?
Simply *collecting* the BSSID is the starting point.
The problem exists no matter what the SSID is.
>>>> I explained it in gory detail, and even provided a link to the research.
>>>> I provided some of the python scripts too (although they're not the
>>>> point).
>>>
>>> You haven't done any of that in this thread so far as I can see.
>>
>> Did you read the paper?
>> What does that paper say?
>
> You hadn't linked the paper at the time I wrote my post.
> The paper doesn't quite say what you're claiming, I think,
> although I see your general point (or at least, the paper's
> authors' general point).
I appreciate that you're the only person in this thread who has ever shown
any indication that you actually clicked on the link, so I must be careful
to let you know that I understand that you went to that trouble to "try" to
understand what the paper actually said.
Remember, I go further than what the paper said, because the paper didn't
discuss hidden broadcast implications, but do keep in mind I wrote the
scripts so I can track any router AP anywhere in the world myself, just as
the paper claimed I could.
With my congratulations to you and with my appreciation that you are the
only one who has shown they have read the paper, I must point out that I
think you misunderstood which BSSID the paper is talking about.
For most home routers, the owner has no way of changing the AP BSSID.
>> Do you know what a hidden broadcast SSID is?
>> What is the purpose of a hidden broadcast in your opinion?
>
> To waste power in client devices, as far as I can see, since it
> means they have to be constantly pinging for the network rather
> than just connecting to it when they see the SSID broadcast.
No. Every mobile device has the on/off ability to NOT autoconnect.
Privacy never was something that everyone could understand, but let's hope
the people on this ng have the capacity to understand the complexities.
> So in some senses it makes the user tracking problem *much worse*,
> since it means the attacker can hang around public places watching
> for client devices (which, unlike access points, tend to move around
> with the user) that are pinging for the attack target's hidden SSID.
That's why you set the mobile device to NOT autoconnect after all.
Remember, privacy doesn't mean you don't have to understand networking.
> Hang around a diner near Langley, Virginia, watching for people
> carrying devices pinging the hidden SSID "CIA UNCLASSIFIED"...
I'm very happy you understand networking at that level, Jon.
This is an extremely well known phenomenon, which has been the topic of
discussion in numerous hackers' conferences, where the presenter puts on
the projector screen the names and locations of all such requests.
Anyone who doesn't understand what we're conversing about, can't really add
value to the conversation, so I'm glad you know it at that level.
>> I've explained both perhaps a half dozen times in this thread.
>> Explaining another half dozen times won't help until you do the above.
>
> I'm starting to think that by "this thread" you don't mean "the set
> of Usenet articles referenced in the References headers" and are
> including other historic threads...
All the python scripts I wrote I put into the public domain so you're
welcome to ask for any of those scripts, which I posted to these ngs.
>> Google does one thing (which, surprisingly, is the right thing to do).
>> Apple does the opposite (and, not surprisingly, refuses to change it).
>
> I think you are still failing to explain what those two things are,
> and I'm getting tired of guessing. If you are claiming the paper
> describes this difference, please say where. If it doesn't, please
> just say what it is.
Again, I have to first say that I appreciate that you read the paper, and I
presume you read the Mozilla documentation I presented, and I presume you
also read the Apple documentation which the Apple lawyers wrote after my
discussions with them way back in December of last year (public knowledge).
The paper shows that Apple's WPS implementation is highly flawed.
If you've ever tried Google's WPS implementation, you'll see that it's not.
Nor is Mozilla's MLS implementation (now deprecated).
This is known public information that I have to assume you already know, as
it would take me a while to write the Python scripts to query Google's
implementation, which also requires a key which is well known data.
SO, while I do appreciate that you're 'trying' to understand, to have me
document what Google has already documented, would be a waste of energy.
It's absurd for anyone to dispute what I say without actually looking up
the extremely well known fact that the Google lookup requires not only a
key from Google but also it's limited in what it outputs, and also it's
limited in how many lookups you can do in a certain time period.
Apple's WPS lookup is not.
That's why they wrote that paper, after all... :)
--
What is disconcerting is nobody seems to look anything up even as everyone
in the world knows what I'm explaining in this thread, over & over again.
[toc] | [prev] | [next] | [standalone]
| From | Jon Ribbens <jon+usenet@unequivocal.eu> |
|---|---|
| Date | 2026-09-06 00:06 +0000 |
| Message-ID | <slrn119pbka.8k8.jon+usenet@raven.unequivocal.eu> |
| In reply to | #197933 |
Firstly, I do not like crossposting to so many groups. What group are you actually reading this thread in, so that I can limit the crossposts please? On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote: > Jon Ribbens wrote: >>> If you don't know what a BSSID is by now then it will take too much work >>> here to explain it "fully" to you. Suffice to say it's like a vehicle >>> identification number on a car. It goes everywhere the router goes. >> >> Well, yes, it's the MAC address, like I already said. > > Hi Jon, > > To your credit, you are the first person who has responded, who has shown > that he actually *read* the paper before trying to respond intelligently. > > *Surveilling the Masses with Wi-Fi-Based Positioning Systems* > <https://arxiv.org/abs/2405.14975> > > That's good. > Nobody else even bothered to click on the link, before responding. > > Hence, everyone else simply parroted their stone-age knowledge level. > You, at least, did *read* the paper, which I congratulate you for doing. > > But you did not *understand* what the paper said by the BSSID. > See below where you completely whooshed on which BSSID is what matters. > > I must be careful here not to fault you like I fault the Apple trolls, > because I think you are sincerely trying to understand the problem set. > > So I simply caution you, as I did Lawrence & Andy, all of whom I respect > for acumen, that you have to follow the trail of the *router* AP BSSID. > > You can not "randomize the BSSID" of the router AP (except in the most > expensive commercial routers, which are not the topic of this thread). > > Think very deeply about that simple fact before responding, as the crux of > the problem is no different than a governmment-issued identification > number. > > You can't easily change your unique government-issued ID number just as you > can't easily change the router-issued BSSID of your home router AP. Yes, I do know all of the above. > Think about that the same way the paper presented the mass surveillance. > 1. I wrote a Python script that ran on Windows 10 that guessed at a set > of random government-issued identification numbers, e.g., 123.45.6789 > 2. Within minutes, I had a hit on a random government ID, which came > back with a GPS location and 400 nearby government IDs and locations. > 3. Then, I ran another Python script on Windows 10 that extended that, > taking the furthest-away governemtn ID/location pair, and did it again. > 4. Within an hour, I had thousands of government IDs and locations. > (the researchers gathered billions, as I recall, but I stopped there.) > > Now that I have every government-issued ID and GPS location in the world in > my 2TB database (which we calculated would be the size it would have been), > what is the paper saying about "mass surveillance" possibilities? > > HINT: I can track the future location of every one of those billions of > government ID/GPS location pairs, without any restrictions on my scripts! > > Want to prove that? > What's your home router BSSID? > > I will not only tell you exactly where that router is located (I even wrote > the Python code to give me a dot on an OSM map for your location) but I can > trivially easily forever track that router's location forever, without any > restrictions on my part (which is the point of the paper, after all). Yes, I know that too now, after reading the paper. I downloaded the code at https://github.com/darkosancanin/apple_bssid_locator (which was originally uploaded in 2015) and ran it locally with my own AP MAC address and confirmed it showed my home location very accurately. It does concern me that there is an attack model here which is that a mildly technically-inclined stalker can very easily get the BSSID of their victim and, as you say, find out where they've gone if they move house to get away from them. >> It mostly seems to be an attack against people who don't realise >> they are targets, or are not thinking about the implications - c.f. >> soldiers who upload their daily runs to public web sites thus >> revealing if/where they are deployed. > > It's not "an attack" so much as explaining, with examples, of why we > should care that mass surveillance is so easy with the Apple WPS > implementation. We should care because it enables attacks. > Give me your BSSID. > > Note: I don't expect you to do it, which alone proves the point. As above, I already tried it. >> As I say that's a pretty unusual thing to do (travelling with a router). >> Google's API does seem more sensible though (give it MAC addresses, it >> tells you where you probably are, rather than giving you the recorded >> individual locations of all those MAC addresses). > > I think your claim that it's "pretty unusual" for people to take their > router with them when they move from one apartment to another is skewed. > > If I ask 100 people who recently moved, do you really think it would be > only 1 or 2 people who took their home router with them when they moved? I could quibble with that inasmuch as ISPs tend to provide the APs when you order the connection, so a new connection usually implies a new AP (in the UK, anyway). But I was talking about travelling with an AP, e.g. on business, not moving house. >>> You think this tracking isn't happenging asa we speak? >>> You think Apple is doing something about it? >>> >>> That's 1/2 the point of this thread. >>> 1. Apple is doing NOTHING about it (as described in the paper) >> >> Have you, er, read the paper? It says Apple *is* doing things about it >> (page 14, section 10 paragraph 3). > > See my first response to you in this post, where I want to be careful to > not chastise you for misunderstanding what that paragraph actually says. > > You can NOT randomize the MAC address of the router AP, Jon. Yes, I wasn't talking about randomizing the MAC addresses of APs, I was talking about Apple taking steps to mitigate the attacks enabled by their BSSID-lookup API. Apparently adding the "_nomap" exception was one of the things Apple changed. I agree that they shouldn't be storing BSSID data unless they see an SSID broadcast without "_nomap" on the end (i.e. the SSID is not hidden). And although I've briefly explored various lines of thought, I can't immediately see why they would be reluctant to make that change. But... it makes very little difference to the actual possible attacks. Almost nobody hides their SSID, and even fewer append "_nomap". Anyone who actually seriously cares about these things would take the trouble to ensure that their BSSID does change if their location changes (even if that means going as far as buying a new AP). The people who are vulnerable are the people who don't know they're vulnerable. >>> 2. So anyone in the world can track the movements of billions of routers >>> 2. Worse, Apple isn't honoring the established meaning of the hidden >>> broadcast (which even Google honors, by way of stark contrast). >> >> This is the bit I keep asking about and you keep not responding. >> Is your actual/main complaint that Apple is storing BSSIDs that >> correspond to hidden SSIDs? And you're saying only Apple do this, >> not Google etc? > > First off, I don't have a complaint. That's absurd. I have facts. You certainly don't seem to be happy with the status quo, which means that by definition you have a complaint. My point is that for some reason you are being opaque about what change you want to see. > The absurdity of this thread is nobody has read or understood the links > which were provided, and yet, they ask me (repeatedly) to explain them. > > Why can nobody understand the point that Eric & Dave made in this paper? > *Surveilling the Masses with Wi-Fi-Based Positioning Systems* > <https://arxiv.org/abs/2405.14975> > > Why can nobody understand what's different about what Apple documented? > <https://support.apple.com/en-ie/102515> > > Why can nobody undestqand the concept inherent in a hidden-broadcast? > <https://ichnaea.readthedocs.io/en/stable/api/geosubmit2.html> > "The BSSID of the Wifi network. > Hidden Wifi networks must not be collected." > > Why is it that I feel it's trivial to understand that 1+1=2 when everyone > else is trying to claim that I need to explain why 1+2=2 when, if they > simply read (and understood) what I've explained, they would understand? I think that many people understand that 1+1=2, but you are then going on to make some further claim that you are explaining very badly. Also, the links you are providing do not always back up what you are saying, or it is not clear what conclusion you are expecting people to draw from them. For example, that last quote about "Hidden WIFi networks must be be collected" is simply a policy of the Mozilla Location Service. It isn't any sort of law or agreed standard. >>> So much for Apple "cares about your privacy" bullshit, huh? >>> It's shocking that google cares about privacy more than Apple does. >> >> Apple cares about the privacy of *its customers*. > > I realize you're trying to understand these concepts so I have to be > careful when I point out that this affects every single person in the > world who owns a router (and company, but let's restrict this to just > people). > > The issues are exactly the same no matter what company made that router. Yes, I think you missed my point, which is that Apple is not generally the provider of the routers, so Apple is not primarily concerned with the privacy of their owners. Apple is primarily concerned with the privacy of its customers, in respect of them being its customers. (i.e. does their use of an Apple product threaten their privacy?) >> I imagine the issue here is that if they change their API then older >> devices that are no longer receiving updates will stop being able to do >> wifi-positioning. > > The issue is clearly obvious that the Apple WPS design is flawed. > > I have dozens of emails from Apple, all of which show that they *know* > that their design is flawed. > > They're simply trying to protect themselves legally with me by having > their emails redirected to their lawyers, who are whom I was > responding with. > > They *know* what they're doing is wrong. I think all of the above is likely true, but there is some reason they cannot (quickly) change their API, probably related to the millions of devices out there which either can not or do not receive new software updates. >>> Remember the Apple trolls posted to this thread that changing the >>> SSID would solve the issue, but the main issue is about the BSSID, >>> not the SSID. >>> a. The BSSId is unique (see above for rare exceptions). >>> b. The GPS location is also unique >>> c. The SSID only plays a role tangentially, and as such is a minor player >> >> The "Apple trolls" are presumably correct inasmuch as if you change the >> SSID to end in "_nomap" then it solves the issue. > > No it does not. Did you read any of the Mozilla references? > Simply *collecting* the BSSID is the starting point. > > The problem exists no matter what the SSID is. Sorry, I don't get what you mean. If the broadcast SSID ends with "_nomap" then Apple won't store the BSSID, and won't respond with its location. Are you saying that isn't true? If it is true, then what is "the problem"? > With my congratulations to you and with my appreciation that you are the > only one who has shown they have read the paper, I must point out that I > think you misunderstood which BSSID the paper is talking about. > > For most home routers, the owner has no way of changing the AP BSSID. I don't know why you think I misunderstood that. >>> Do you know what a hidden broadcast SSID is? >>> What is the purpose of a hidden broadcast in your opinion? >> >> To waste power in client devices, as far as I can see, since it >> means they have to be constantly pinging for the network rather >> than just connecting to it when they see the SSID broadcast. > > No. Every mobile device has the on/off ability to NOT autoconnect. > > Privacy never was something that everyone could understand, but let's > hope the people on this ng have the capacity to understand the > complexities. I think even fewer people are going to be manually connecting their devices to a hidden-SSID WiFi network every time they come into range than have hidden-SSID WiFi networks in the first place. >> I think you are still failing to explain what those two things are, >> and I'm getting tired of guessing. If you are claiming the paper >> describes this difference, please say where. If it doesn't, please >> just say what it is. > > Again, I have to first say that I appreciate that you read the paper, and I > presume you read the Mozilla documentation I presented, and I presume you > also read the Apple documentation which the Apple lawyers wrote after my > discussions with them way back in December of last year (public knowledge). I read the paper (albeit not in complete detail), and I skimmed the Apple documentation, although I'm not clear on which bit you are saying they added because of you - I assume the "This opt-out doesn’t work for hidden networks" bit? > The paper shows that Apple's WPS implementation is highly flawed. > > If you've ever tried Google's WPS implementation, you'll see that it's > not. Nor is Mozilla's MLS implementation (now deprecated). The paper discusses the difference between Apple and Google's implementation, and I agree that Google's looks better.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-09-06 13:39 +0200 |
| Message-ID | <mvvvmmxm4c.ln2@Telcontar.valinor> |
| In reply to | #197936 |
On 2026-09-06 02:06, Jon Ribbens wrote: > Firstly, I do not like crossposting to so many groups. What group > are you actually reading this thread in, so that I can limit the > crossposts please? I understand, but that could be a problem to people that are already reading on a "different" group. Your comments are easier to understand that Arlen (aka Maria) posts. He is not clearly explaining the issues and wants people to read a lot of documentation, instead of just posting an actual summary of the situation with explanations. Ie, what was Apple doing, why is that bad, what have they changed, is that enough and why, what are the actual dangers to people. Complete, and short text. > > On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote: >> Jon Ribbens wrote: ... >>> As I say that's a pretty unusual thing to do (travelling with a router). >>> Google's API does seem more sensible though (give it MAC addresses, it >>> tells you where you probably are, rather than giving you the recorded >>> individual locations of all those MAC addresses). >> >> I think your claim that it's "pretty unusual" for people to take their >> router with them when they move from one apartment to another is skewed. >> >> If I ask 100 people who recently moved, do you really think it would be >> only 1 or 2 people who took their home router with them when they moved? > > I could quibble with that inasmuch as ISPs tend to provide the APs when > you order the connection, so a new connection usually implies a new AP > (in the UK, anyway). But I was talking about travelling with an AP, > e.g. on business, not moving house. Most people here get a free (rented, not purchased) router with AP from their ISP. When they move house, the old router has to be returned to the ISP (nominally), and they get a new router automatically when contracting a connection at the new location. So they don't have a problem. Some of those might have a secondary AP of their own. Only people that buy a router or AP have a problem. And most do not care. I don't. Only those that are using _nomap or perhaps those that hide the SSID. ... -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Jon Ribbens <jon+usenet@unequivocal.eu> |
|---|---|
| Date | 2026-09-06 15:37 +0000 |
| Message-ID | <slrn119r24u.8k8.jon+usenet@raven.unequivocal.eu> |
| In reply to | #197938 |
On 2026-09-06, Carlos E.R. <robin_listas@es.invalid> wrote:
> On 2026-09-06 02:06, Jon Ribbens wrote:
>> Firstly, I do not like crossposting to so many groups. What group
>> are you actually reading this thread in, so that I can limit the
>> crossposts please?
>
> I understand, but that could be a problem to people that are already
> reading on a "different" group.
>
> Your comments are easier to understand that Arlen (aka Maria) posts. He
> is not clearly explaining the issues and wants people to read a lot of
> documentation, instead of just posting an actual summary of the
> situation with explanations.
>
> Ie, what was Apple doing, why is that bad, what have they changed, is
> that enough and why, what are the actual dangers to people.
>
> Complete, and short text.
Ok, well to summarise what I have gathered then, which may or may not
be Maria's opinion but reflects my opinion at this point: there are two
completely separate issues here, which are unrelated except that they
are both to do with WiFi location databases.
1. Apple are storing the location of "hidden" WiFi Access Points.
(My opinion: low priority.)
Multiple organisations are gathering and storing the physical
co-ordinates of the MAC addresses ("BSSIDs") of WiFi Access Points
around the world, whenever they are seen transmitting by, e.g. mobile
phones. (Any WiFi-enabled device can see this information; it does not
need to be connected to the network in question, nor does it need to
know its password.)
The purpose of these databases of BSSID locations is to assist devices
such as mobile phones in locating themselves. Maybe the device is
indoors and cannot get a GPS signal, but also my understanding is that
GPS can fix an accurate location much faster if it starts already
knowing vaguely where on the planet it is.
There is broad agreement that these databases should not include BSSIDs
which are broadcasting WiFi network names ("SSIDs") which end in the
string "_nomap".
Allegedly: Apple are adhering to this exclusion, but are not also
excluding BSSIDs which are not broadcasting any SSID at all (i.e.
"hidden" networks). Other organisations (e.g. Google) do exclude such
"hidden" networks.
My complete speculation: older Apple software, written before they added
the "_nomap" exclusion, doesn't care at all about the SSID, so just
reports from the phone to the central database the BSSID and location.
The database thus has no way of excluding "hidden" networks, without
excluding all reports from older devices. The "_nomap" exclusion is
achieved by later software versions reporting the SSID if it is seen,
and any BSSIDs associated with "_nomap" SSIDs then being blacklisted,
maybe for 6 months or something like that. The likelihood of any
particular BSSID *only* being seen by old Apple devices and *never* new
ones is very low, and hence the "_nomap" exclusion more-or-less works.
My opinion: this failure to exclude "hidden" networks is unfortunate and
should be fixed, and maybe Apple are indeed fixing it, but it's possible
it may take some years to achieve due to the multitude of devices
running old software.
2. Apple's API is trivial to abuse.
(My opinion: high priority.)
The Apple API to query their BSSID location database is remarkably
unrestricted. It has little or no rate limiting, doesn't ask for an API
key, and reports not only the location of the BSSID but also potentially
a great many other BSSIDs in the locality. It is not beyond even an
individual person's ability to get a list of most of the Access Points
in the world and all their locations.
This makes it very easy for people to abuse this data in various ways,
from stalkers tracking victims to state actors tracking military
targets.
Google's API by contrast essentially reverses the process, and instead
of the phone asking "Where is BSSID <x>?", it says "I can see BSSIDs
<x>, <y>, and <z>, where am I?".
My opinion: the lack of restrictions on the Apple API is unacceptable,
and if Apple are unwilling to do something about it then governments
should pass laws (or enforce existing laws) to make them to do so.
My opinion: it would be difficult for Apple to rapidly switch completely
to using an API more similar to Google's API, since this would remove
functionality from devices running old software. However they could
certainly aim to do this eventually, and there are steps they could take
immediately to improve the situation (e.g. rate limiting, and not
providing so many additional answers when asked about an individual
BSSID). I cannot see any obvious reason why they couldn't make
significant improvements almost immediately.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-09-06 20:23 +0200 |
| Message-ID | <vln0nmxs7v.ln2@Telcontar.valinor> |
| In reply to | #197942 |
On 2026-09-06 17:37, Jon Ribbens wrote:
> On 2026-09-06, Carlos E.R. <robin_listas@es.invalid> wrote:
>> On 2026-09-06 02:06, Jon Ribbens wrote:
>>> Firstly, I do not like crossposting to so many groups. What group
>>> are you actually reading this thread in, so that I can limit the
>>> crossposts please?
>>
>> I understand, but that could be a problem to people that are already
>> reading on a "different" group.
>>
>> Your comments are easier to understand that Arlen (aka Maria) posts. He
>> is not clearly explaining the issues and wants people to read a lot of
>> documentation, instead of just posting an actual summary of the
>> situation with explanations.
>>
>> Ie, what was Apple doing, why is that bad, what have they changed, is
>> that enough and why, what are the actual dangers to people.
>>
>> Complete, and short text.
>
> Ok, well to summarise what I have gathered then, which may or may not
> be Maria's opinion but reflects my opinion at this point: there are two
> completely separate issues here, which are unrelated except that they
> are both to do with WiFi location databases.
Thanks.
>
>
> 1. Apple are storing the location of "hidden" WiFi Access Points.
> (My opinion: low priority.)
Only Apple?
>
> Multiple organisations are gathering and storing the physical
> co-ordinates of the MAC addresses ("BSSIDs") of WiFi Access Points
> around the world, whenever they are seen transmitting by, e.g. mobile
> phones. (Any WiFi-enabled device can see this information; it does not
> need to be connected to the network in question, nor does it need to
> know its password.)
Yes.
> The purpose of these databases of BSSID locations is to assist devices
> such as mobile phones in locating themselves. Maybe the device is
> indoors and cannot get a GPS signal, but also my understanding is that
> GPS can fix an accurate location much faster if it starts already
> knowing vaguely where on the planet it is.
Yes. And they can give an approximate location without using the GPS chip.
>
> There is broad agreement that these databases should not include BSSIDs
> which are broadcasting WiFi network names ("SSIDs") which end in the
> string "_nomap".
Right.
>
> Allegedly: Apple are adhering to this exclusion, but are not also
> excluding BSSIDs which are not broadcasting any SSID at all (i.e.
> "hidden" networks). Other organisations (e.g. Google) do exclude such
> "hidden" networks.
And if it is hidden they would not see if the SSID ends in _nomap.
But is there a consensus that hidden SSIDs should not be listed? In
writing? Maybe there is such a consensus now.
>
> My complete speculation: older Apple software, written before they added
> the "_nomap" exclusion, doesn't care at all about the SSID, so just
> reports from the phone to the central database the BSSID and location.
> The database thus has no way of excluding "hidden" networks, without
> excluding all reports from older devices. The "_nomap" exclusion is
> achieved by later software versions reporting the SSID if it is seen,
> and any BSSIDs associated with "_nomap" SSIDs then being blacklisted,
> maybe for 6 months or something like that. The likelihood of any
> particular BSSID *only* being seen by old Apple devices and *never* new
> ones is very low, and hence the "_nomap" exclusion more-or-less works.
>
> My opinion: this failure to exclude "hidden" networks is unfortunate and
> should be fixed, and maybe Apple are indeed fixing it, but it's possible
> it may take some years to achieve due to the multitude of devices
> running old software.
Right.
Related: What did Arlen (aka Maria) achieve? That Apple agreed to remove
all hidden and _nomap entries, or that they removed only his entry?
> 2. Apple's API is trivial to abuse.
> (My opinion: high priority.)
>
> The Apple API to query their BSSID location database is remarkably
> unrestricted. It has little or no rate limiting, doesn't ask for an API
> key, and reports not only the location of the BSSID but also potentially
> a great many other BSSIDs in the locality. It is not beyond even an
> individual person's ability to get a list of most of the Access Points
> in the world and all their locations.
Aha.
>
> This makes it very easy for people to abuse this data in various ways,
> from stalkers tracking victims to state actors tracking military
> targets.
Well, only of the limited subset of people that carry their AP when they
move.
> Google's API by contrast essentially reverses the process, and instead
> of the phone asking "Where is BSSID <x>?", it says "I can see BSSIDs
> <x>, <y>, and <z>, where am I?".
Ah. Yes, I can see this is better.
>
> My opinion: the lack of restrictions on the Apple API is unacceptable,
> and if Apple are unwilling to do something about it then governments
> should pass laws (or enforce existing laws) to make them to do so.
>
Ok.
> My opinion: it would be difficult for Apple to rapidly switch completely
> to using an API more similar to Google's API, since this would remove
> functionality from devices running old software. However they could
> certainly aim to do this eventually, and there are steps they could take
> immediately to improve the situation (e.g. rate limiting, and not
> providing so many additional answers when asked about an individual
> BSSID). I cannot see any obvious reason why they couldn't make
> significant improvements almost immediately.
Ok, yes.
Thank you for the explanation. Easy to understand, and I agree with your
conclusions.
--
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| Date | 2026-09-07 02:16 +0300 |
| Message-ID | <117ks8d$jjt$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #197945 |
After having read the prior responses in this Jon/Carlos tangent... I apologize if I haven't explained the situation to the liking of people who haven't clicked on the references, but I am happy that Jon and Carlos (and Andy and Lawrence, all of whom I respect) are trying to understand. I especially wish to thank Jon Ribbens and Carlos & any others who have bothered to read the links provided, because they explain the issue well. If people haven't read the references, then they're stuck in the stone age of understanding, which, well, which I'm not the one to drag them out of. I just don't have the skills to explain that an SSID is not a BSSID (as witnessed by those who claimed changing the SSID changes the BSSID). These are basic networking concepts. Regarding locations, I don't have the skills to explain what a set of GPS coordinates means, if people claim it's "just a map". I don't even know _how_ to _begin_ to explain that your home address is NOT "just a map". I don't even know how to explain to people who claim that the router never travels as their belief system is so absurd as to warn me that if they don't understand that people take their routers with them when they move, then that kind of person will never be able to understand, well, anything. I apologize that I don't have the skills set to bring folks out of the stone age, when they claim a home address is "just a location on a map". People who make those claims will never be able to comprehend why it is so trivial for Jon & me to surveil their movements using the Apple WPS db. In summary, if people haven't read this paper, I don't have the skill set to explain the very simple concepts which are described in that paper. *Surveilling the Masses with Wi-Fi-Based Positioning Systems* <https://arxiv.org/abs/2405.14975> The paper is about surveillance of masses (not individuals, per se), knowing every single location of billions of router BSSIDs around the world, from anywhere in the world, by anyone in the world, with zero restrictions, which is only possible using Apple's WPS database (not Google's, which has huge restrictions on both the input and output). Apple has zero restrictions on the input. And a restriction of the nearest 400 BSSIDs/GPS pairs on the output. But... that restriction is meaningless, as I wrote and ran the Python code on Windows that took the furthest away of those 400 to run it again. And again. And again. And again. I stopped at something like thousands. So now I have the nearest ten thousand BSSIDs starting at my home. Notice I have the GPS location of each of those unique ten thousand BSSIDs. And, since apartments basically do not exist in this suburban area, I actually know the names and address of the owners of record of those homes. If any of those ten thousand people ever move, and take their router with them, I will instantly know exactly where they moved to, within seconds. Not only that, but I will instantly know the nearest 400 BSSIds, so if they moved, oh, say, into someone else's home, I'll know exactly who that is. To be very clear, this is only possible because of how Apple designed it. Google and Mozilla designed their systems completely differently. Only Apple's design is this bad in terms of privacy. As for the hidden-BSSID issue, I was unaware of that until I found, to my horror, my own hidden BSSIDs in Apple's WPS database. That was a shock! At the time, I looked up Apple's public policy, and it was silent on the issue of what Apple does when it encounters a hidden-broadcast BSSID. When I brought it up to my next-door neighbor, who runs Apple Maps, he said he'd check it out, which, after a few weeks of emails back and forth, we found out that Apple has no intention of honoring the intent of a hidden broadcast (even as we know Google & Mozilla certainly honor that intent). The Apple lawyers made that very clear to me, as I was shut out from talking to the engineers once the lawyers were informed of the issue. I had given up, but recently, I happened to look at Apple's documentation, and I realized Apple proved they had no intent of honoring the long-held intention of a hidden broadcast, by simply changing their documentation. <https://support.apple.com/en-ie/102515> Clearly, I know what I'm talking about, so my well informed assessment, based on those verifiable facts, is Apple doesn't care about our privacy. -- On Usenet we can have intelligent discussions with well-meaning people.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-09-07 13:42 +0200 |
| Message-ID | <ghk2nmx99u.ln2@Telcontar.valinor> |
| In reply to | #197951 |
On 2026-09-07 01:16, Maria Sophia wrote: > After having read the prior responses in this Jon/Carlos tangent... > > I apologize if I haven't explained the situation to the liking of people > who haven't clicked on the references, but I am happy that Jon and Carlos > (and Andy and Lawrence, all of whom I respect) are trying to understand. > > I especially wish to thank Jon Ribbens and Carlos & any others who have > bothered to read the links provided, because they explain the issue well. > > If people haven't read the references, then they're stuck in the stone age > of understanding, which, well, which I'm not the one to drag them out of. > > I just don't have the skills to explain that an SSID is not a BSSID > (as witnessed by those who claimed changing the SSID changes the BSSID). > > These are basic networking concepts. We didn't ask to have it explained. Knowing this is not about skills, though. A mathematician can have very high skills, yet know nothing about networks. Even a skilled computer programmer may not know about them, and be a world master on IBM big iron assembler programming (and being paid handsomely - a tiny fact I happen to know) and not know offhand what the BSSID is. > Regarding locations, I don't have the skills to explain what a set of GPS > coordinates means, if people claim it's "just a map". I don't even know > _how_ to _begin_ to explain that your home address is NOT "just a map". > > I don't even know how to explain to people who claim that the router never > travels as their belief system is so absurd as to warn me that if they > don't understand that people take their routers with them when they move, > then that kind of person will never be able to understand, well, anything. No, we don't travel with our routers. My router belongs to the ISP and I have to return it when I move, then I will get a new one at my destination. You should be intelligent enough to accept this. Maybe doesn't happen in your nook of the world, but you must understand that you are posting to an international medium. > > I apologize that I don't have the skills set to bring folks out of the > stone age, when they claim a home address is "just a location on a map". Don't be insulting. You can say the same things without insulting people or being patronizing. ... > When I brought it up to my next-door neighbor, who runs Apple Maps, he said > he'd check it out, which, after a few weeks of emails back and forth, we > found out that Apple has no intention of honoring the intent of a hidden > broadcast (even as we know Google & Mozilla certainly honor that intent). > > The Apple lawyers made that very clear to me, as I was shut out from > talking to the engineers once the lawyers were informed of the issue. > > I had given up, but recently, I happened to look at Apple's documentation, > and I realized Apple proved they had no intent of honoring the long-held > intention of a hidden broadcast, by simply changing their documentation. > <https://support.apple.com/en-ie/102515> Ok, finally. The crux of the issue. > > Clearly, I know what I'm talking about, so my well informed assessment, > based on those verifiable facts, is Apple doesn't care about our privacy. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| Date | 2026-09-07 21:06 +0300 |
| Message-ID | <117muff$1821$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #197974 |
Carlos E.R. wrote: >> These are basic networking concepts. > > We didn't ask to have it explained. Knowing this is not about skills, > though. A mathematician can have very high skills, yet know nothing > about networks. Even a skilled computer programmer may not know about > them, and be a world master on IBM big iron assembler programming (and > being paid handsomely - a tiny fact I happen to know) and not know > offhand what the BSSID is. Hi Carlos, The facts are incontrovertible, where only Jon went to the trouble to reproduce them (AFAwK). Everyone else simply used their stone-age knowledge of networking (which we all knew decades ago) to apply to this thread. Winston just did that, multiple times in this thread, as if stating his own stone-age knowledge of networking has anything to do whatsoever with the topic. Franklin Slootweg tried the same worthless trolling as Winston did. Please note that there's nothing wrong with people's stone-age knowledge of networking, but their stone-age knowledge, while true, doesn't apply here. If all they can do in response to the facts posted in this thread is repeat their stone-age thought processes, then they can't possibly add value. Then you have the trolls like Keith Thompson claiming that running python on Windows to prove what Apple & Android devices do by default with respect to Wi-Fi protocols has absolutely nothing to do with running python on windows to prove how Apple & Google devices differ from how they handle Wi-Fi metadata. WTF? These people are all applying their stone-age knowledge of networking, but without taking into account the verified *new* information in this thread. Not a single person who trolled this thread shows any understanding of it. >> I don't even know how to explain to people who claim that the router never >> travels as their belief system is so absurd as to warn me that if they >> don't understand that people take their routers with them when they move, >> then that kind of person will never be able to understand, well, anything. > > No, we don't travel with our routers. > > My router belongs to the ISP and I have to return it when I move, then I > will get a new one at my destination. You should be intelligent enough > to accept this. Maybe doesn't happen in your nook of the world, but you > must understand that you are posting to an international medium. WTF? What kind of absurd arguments are you claiming Carlos? I don't like broccoli, so nobody on the planet likes broccoli? More to the point, I don't bring the paintings on my wall with me when I move, but that doesn't mean that nobody brings their paintings with them. The fact you get your access point from the ISP, while true, is an absurd way of your attempt to refute the facts proposed in this respected paper. *Surveilling the Masses with Wi-Fi-Based Positioning Systems* <https://arxiv.org/abs/2405.14975> I do take my many access points with me, Carlos. Dozens of them. And even if I didn't, it would still refute NOTHING in that research paper. The fact that's your major rebuttal indicates you haven't read the paper. Read it. Please. >> I had given up, but recently, I happened to look at Apple's documentation, >> and I realized Apple proved they had no intent of honoring the long-held >> intention of a hidden broadcast, by simply changing their documentation. >> <https://support.apple.com/en-ie/102515> > > Ok, finally. The crux of the issue. It's not hidden. It is, after all, in the SUBJECT line of this thread, Carlos. Every person who tried it, found out every single statement to be true. -- My role on Usenet is to always add value that other people aren't aware of.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-09-07 21:28 +0200 |
| Message-ID | <nsf3nmxviq.ln2@Telcontar.valinor> |
| In reply to | #197979 |
On 2026-09-07 20:06, Maria Sophia wrote: > Carlos E.R. wrote: >>> These are basic networking concepts. >> >> We didn't ask to have it explained. Knowing this is not about skills, >> though. A mathematician can have very high skills, yet know nothing >> about networks. Even a skilled computer programmer may not know about >> them, and be a world master on IBM big iron assembler programming (and >> being paid handsomely - a tiny fact I happen to know) and not know >> offhand what the BSSID is. > > Hi Carlos, > > The facts are incontrovertible, where only Jon went to the trouble to > reproduce them (AFAwK). Everyone else simply used their stone-age knowledge > of networking (which we all knew decades ago) to apply to this thread. > > Winston just did that, multiple times in this thread, as if stating his own > stone-age knowledge of networking has anything to do whatsoever with the > topic. Franklin Slootweg tried the same worthless trolling as Winston did. > > Please note that there's nothing wrong with people's stone-age knowledge of > networking, but their stone-age knowledge, while true, doesn't apply here. > > If all they can do in response to the facts posted in this thread is repeat > their stone-age thought processes, then they can't possibly add value. > > Then you have the trolls like Keith Thompson claiming that running python > on Windows to prove what Apple & Android devices do by default with respect > to Wi-Fi protocols has absolutely nothing to do with running python on > windows to prove how Apple & Google devices differ from how they handle > Wi-Fi metadata. > > WTF? Wrong. Keith Thompson argues that your post is off topic in comp.lang.python, because you are not discussing python code. You simply posted a link that contains a reference to a Python program and said you run it. You are not discussing the code itself or making any question about it. And he is right, IMNSHO. > > These people are all applying their stone-age knowledge of networking, but > without taking into account the verified *new* information in this thread. > > Not a single person who trolled this thread shows any understanding of it. > >>> I don't even know how to explain to people who claim that the router never >>> travels as their belief system is so absurd as to warn me that if they >>> don't understand that people take their routers with them when they move, >>> then that kind of person will never be able to understand, well, anything. >> >> No, we don't travel with our routers. >> >> My router belongs to the ISP and I have to return it when I move, then I >> will get a new one at my destination. You should be intelligent enough >> to accept this. Maybe doesn't happen in your nook of the world, but you >> must understand that you are posting to an international medium. > > WTF? > What kind of absurd arguments are you claiming Carlos? It is fact, Arlen. > > I don't like broccoli, so nobody on the planet likes broccoli? > > More to the point, I don't bring the paintings on my wall with me when I > move, but that doesn't mean that nobody brings their paintings with them. > I did not say "nobody". That's you reading what is not in what I said. > The fact you get your access point from the ISP, while true, is an absurd > way of your attempt to refute the facts proposed in this respected paper. I don't refute anything, except that you can only track a minority of users worldwide. > > *Surveilling the Masses with Wi-Fi-Based Positioning Systems* > <https://arxiv.org/abs/2405.14975> > > I do take my many access points with me, Carlos. Dozens of them. > And even if I didn't, it would still refute NOTHING in that research paper. > > The fact that's your major rebuttal indicates you haven't read the paper. > Read it. Please. No. > >>> I had given up, but recently, I happened to look at Apple's documentation, >>> and I realized Apple proved they had no intent of honoring the long-held >>> intention of a hidden broadcast, by simply changing their documentation. >>> <https://support.apple.com/en-ie/102515> >> >> Ok, finally. The crux of the issue. > > It's not hidden. > It is, after all, in the SUBJECT line of this thread, Carlos. > > Every person who tried it, found out every single statement to be true. It is good Usenet manners to explain the subject in the body. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Maria Sophia <mariasophia@comprehension.com> |
|---|---|
| Date | 2026-09-08 06:38 +0300 |
| Message-ID | <117nvvq$2j14$1@nnrp.usenet.blueworldhosting.com> |
| In reply to | #197982 |
Carlos E.R. wrote: > Keith Thompson argues that your post is off topic in comp.lang.python, > because you are not discussing python code. You simply posted a link > that contains a reference to a Python program and said you run it. You > are not discussing the code itself or making any question about it. > > And he is right, IMNSHO. People can't understand what the issue is if they don't understand the breadcrumb trail from your router access point to my Win10 python runs. They just can't. Their stone-age knowledge of networking doesn't prepare them for it. Keith didn't understand that you have to run the python code that was pointed to in the very first post, Carlos, which Jon found easily. The instant I read the paper, I found and ran the Python code on Win10. Why can Jon and I do it, but Keith complains he can't read the paper? BTW, Keith can whine all he wants that Python code isn't python code. But it's clear he's just whining about something he didn't even read. >> More to the point, I don't bring the paintings on my wall with me when I >> move, but that doesn't mean that nobody brings their paintings with them. >> > > I did not say "nobody". That's you reading what is not in what I said. Jesus Christ, Carlos. Have you never once taken a course in basic logic? Because you don't own a red car, you claim (in effect) red cars can't exist. Your entire rebuttal consist of that? WTF? It's ridiculous. For some odd reason, your claim that because you do it one way, that you think that refutes the fact that BILLIONS of people do it differently. I wouldn't mind if you made that preposterous argument only once, as I'd only need to point out your nonsensical bizarre point of view only once. But you've been foisting that grotesque farcical rebuttal on us since we started investigating this issue, oh, since way back in December 2026. When will you stop proposing that absurd rebuttal that the fact you don't own a red car, you think, negates the fact that billions of other people can own red cars? >> The fact you get your access point from the ISP, while true, is an absurd >> way of your attempt to refute the facts proposed in this respected paper. > > I don't refute anything, except that you can only track a minority of > users worldwide. Clearly you did not read the paper. Read it Carlos. *Surveilling the Masses with Wi-Fi-Based Positioning Systems* <https://arxiv.org/abs/2405.14975> Do not respond until you've shown you read the paper, please. >> The fact that's your major rebuttal indicates you haven't read the paper. >> Read it. Please. > > No. If someone hasn't read the paper, they can't possibly understand the issue. *Surveilling the Masses with Wi-Fi-Based Positioning Systems* <https://arxiv.org/abs/2405.14975> >> Every person who tried it, found out every single statement to be true. > > It is good Usenet manners to explain the subject in the body. The subject says: a. Apple changed their documentation b. at my request c. but it proves they don't care about privacy Since we provided the old documentation in the past, those trolls (like Winston) who said there's no "proof", were simply trolling us, as they didn't even read to know it never said that until after I contacted them. At my request, would be hard for anyone here to verify, although the time points all line up, as you all know I complained about this back in December, and I stated then, that I had my neighbor file the RADAR report. I also stated at that time, they removed my hidden BSSID, but I'm likely the only one in the world who has had that favor (as far as we would know). The part about privacy is harder for people on this group to comprehend since they're all seemingly stuck in the stone age of wireless networking. They don't know how to follow the BSSID/GPS breadcrumb trail from an iOS or Android device (as it's very different!) to the Apple or Google database (as that's different too!) and eventually to the Python code that Keith says doesn't exist but which both Jon and I dutifully ran to confirm. To put it bluntly, everyone but Apple will NOT distribute your BSSID if it's hidden broadcast. Only Apple refuses to abide by that convention.
[toc] | [prev] | [next] | [standalone]
Page 1 of 5 [1] 2 3 4 5 Next page →
Back to top | Article view | comp.lang.python
csiph-web